Skip to content

Fix RSA PKCS#1 v1.5 forgery via nested DigestAlgorithm garbage - #1152

Open
Krysthyan wants to merge 1 commit into
digitalbazaar:mainfrom
Krysthyan:fix/cve-2026-85393-digestalgorithm-element-count
Open

Krysthyan wants to merge 1 commit into
digitalbazaar:mainfrom
Krysthyan:fix/cve-2026-85393-digestalgorithm-element-count

Conversation

@Krysthyan

@Krysthyan Krysthyan commented Sep 9, 2026 •

Copy link
Copy Markdown

Summary

Test plan

  • Reproduction: forged EM with DigestAlgorithm children [OID, NULL, garbage] verified as true before the change; throws invalid DigestInfo after.
  • Added regression test should check nested DigestAlgorithm element count in tests/unit/rsa.js.
  • npx mocha tests/unit/rsa.js — 101 passing, 4 pending.
  • CHANGELOG Security + Fixed entries for 1.4.1.

Related: #1151 (same issue; this PR uses obj.value[0].value.length instead of adding captureAsn1).

Require DigestAlgorithm SEQUENCE element count (OID + optional NULL) so
asn1.validate cannot ignore interior padding that bypasses CVE-2026-33894.

Co-authored-by: Cursor <cursoragent@cursor.com>
@Zelzazor

Copy link
Copy Markdown

Hi @Krysthyan

I can get behind this solution instead of the one I've made, since it's simpler and does not introduce the potential overhead of adding captureAsn1 to check the same thing.

Have you run the rest of the suites just in case they also pass?

@davidlehn can you check this? The CVE is blocking several pipelines as much as I can see in the mentions of #1149

I will close my PR in favor of this one.

@gwenael-louandre

Copy link
Copy Markdown

Would it be possible to review this PR? We have a vulnerability on our application due to it.
image

Brad-Edwards added a commit to Brad-Edwards/shifter that referenced this pull request Oct 2, 2026
osv-scanner flags node-forge@1.4.0 (CVE-2026-85393 / GHSA-86w9-cpqp-85rv, an
incomplete fix for CVE-2026-33894) in the Identity Platform blocking function's
dependency tree. node-forge is the latest published version, the advisory has no
fixed release (upstream digitalbazaar/forge#1152 is unmerged), and the parent
gcip-cloud-functions@0.2.1 still requires node-forge@^1.3.1, so there is no
upgrade path.

node-forge is pulled in only transitively and is never imported: the SDK runtime
(gcip-cloud-functions/lib/**) contains no require('node-forge'), and the inbound
Identity Platform event JWT is verified via jsonwebtoken (Node crypto). Rather
than ship dormant vulnerable crypto, replace the unused implementation with a
documented local no-op: declare node-forge as a direct file: dependency on
vendor/node-forge (version 1.4.1, just past the affected <=1.4.0 range and still
satisfying the SDK's ^1.3.1), so npm installs only this local copy and no
vulnerable node-forge enters the tree or the committed lockfile. The function's
own tests still pass, confirming node-forge is not exercised.

Remove vendor/node-forge and this dependency once upstream ships a fixed release.
ogabasseyy added a commit to ogabasseyy/Baci that referenced this pull request Oct 2, 2026
hono override 4.13.5 -> 4.13.7 (GHSA-hxh3-vqpv-xpqv boundary XSS). node-forge has no fixed release, so backport upstream digitalbazaar/forge#1152 as a pnpm patch (byte-identical to upstream post-image) with a patch-integrity test; dev-tooling-only reachability via @expo/cli.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

RSA PKCS#1 v1.5 signature forgery via garbage in DigestAlgorithm (incomplete CVE-2026-33894 fix)

5 participants